Gnu sasl
This hub aggregates every CVE we track for Gnu sasl, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
3
CVEs tracked
0
Critical
1
High
0
In CISA KEV
Severity distribution
LOW2HIGH1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
1
0
0
2024-092026-08
Latest CVEs
The 3 most recently published vulnerabilities affecting Gnu sasl.
- CVE-2026-56968GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.3.7
- CVE-2026-48829In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.7.5
- CVE-2022-2469GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client3.8
Product normalization is registry-driven with AI assist and human review. How it works